vendor:
DT741 Converged Intelligent Terminal (G/EPON+IPTV)
by:
Kaustubh G. Padwad
9.8
CVSS
CRITICAL
Stack Overflow
119
CWE
Product Name: DT741 Converged Intelligent Terminal (G/EPON+IPTV)
Affected Version From: Multiple versions
Affected Version To: Multiple versions
Patch Exists: Yes
Related CWE: CVE-2018-19524
CPE: h:shenzhen_skyworth_digital_technology_company_ltd:dt741_converged_intelligent_terminal_g/epon+iptv
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Unauthenticated Stack Overflow in Multiple Gpon Devices
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1,DT721-cb SDOTBGN1,and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S7.
Mitigation:
Upgrade to the latest version of the firmware, Disable the web_passwd function